Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.10%—Cloudfoundry Bosh DirectorAIVmware VcenterAI29/8/20263/9/2026
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic…
AnalizadaCrítica (9.8)2.6%⚠ Explotación activaVmware Vcenter Server30/7/202619/8/2026
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
AnalizadaCrítica (9.8)0.61%—Vmware Vcenter Server30/7/202625/8/2026
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
AplazadaAlta (8.5)0.64%—Vmware VcenterAI29/9/202517/6/2026
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
AplazadaAlta (7.6)0.28%—Vmware ToolsAIVmware VcenterAIVmware ESXAI29/9/202517/6/2026
VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation…
AplazadaMedia (4.4)0.29%—Vmware VcenterAI29/7/202517/6/2026
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.
AplazadaAlta (8.7)0.30%—HPE Oneview FOR Vmware VcenterAI26/6/202517/6/2026
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).
AplazadaMedia (4.3)0.89%—Vmware EsxiAIVmware Vcenter ServerAI20/5/202517/6/2026
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
AplazadaMedia (6.8)0.24%—Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI20/5/202517/6/2026
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools…
AplazadaAlta (8.8)0.26%—Vmware Vcenter ServerAI20/5/202517/6/2026
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
AnalizadaCrítica (9.8)17%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
AnalizadaCrítica (9.8)55%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server17/9/202417/6/2026
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaMedia (5.3)0.71%—Vmware Cloud FoundationVmware Vcenter Server25/6/202417/6/2026
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
AplazadaMedia (4.4)0.14%—Hitachi Storage Provider FOR Vmware VcenterAI25/6/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.
AnalizadaAlta (7.8)5.0%—Vmware Vcenter ServerVmware Cloud Foundation18/6/202417/6/2026
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
ModificadaCrítica (9.8)12%—Vmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaCrítica (9.8)22%⚠ Explotación activaVmware Cloud FoundationVmware Vcenter Server18/6/202417/6/2026
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
AnalizadaMedia (4.9)0.99%—Vmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
AnalizadaAlta (7.2)2.5%—Vmware Cloud FoundationVmware Vcenter Server21/5/202417/6/2026
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
ModificadaMedia (4.3)0.67%—Vmware Vcenter Server25/10/202317/6/2026
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
AnalizadaCrítica (9.8)99%⚠ Explotación activaVmware Vcenter Server25/10/202317/6/2026
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
ModificadaAlta (7.5)0.90%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and…
ModificadaCrítica (9.8)1.4%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
ModificadaCrítica (9.8)34%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
ModificadaCrítica (9.8)1.2%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.